Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
5.3MEDIUMNVD
OSV8.6
EPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedSep 26
Latest updateDec 6

Description

Informational: No Impact of CUPS Vulnerabilities on Palo Alto Networks Products The Palo Alto Networks Product Security Assurance team has evaluated CVE-2024-47076, CVE-2024-47177, CVE-2024-47175, and CVE-2024-47176 in the Common UNIX Printing System (CUPS) as they relate to our products. Based on current information, Palo Alto Networks products and cloud services do not contain affected CUPS-related software packages and are not impacted by these issues. Affected products: Cloud NGFW, Cortex

Affected Packages17 packages

🔴Vulnerability Details

1
OSV
CVE-2024-47176: CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto2024-09-26

💥Exploits & PoCs

1
Metasploit
CUPS IPP Attributes LAN Remote Code Execution

🔍Detection Rules

6
Suricata
ET INFO Observed Server Responding with PDD File With Known Dangerous/Exploitable Parameter2024-09-26
Elastic
Network Connection by Cups or Foomatic-rip Child
Elastic
Suspicious Execution from Foomatic-rip or Cupsd Parent
Elastic
Cupsd or Foomatic-rip Shell Execution
Elastic
File Creation by Cups or Foomatic-rip Child

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-471772024-10-29
Palo Alto
Informational: No Impact of CUPS Vulnerabilities on Palo Alto Networks Products2024-09-26
Red Hat
cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source2024-09-26
Debian
CVE-2024-47176: cups-filters - CUPS is a standards-based, open-source printing system, and `cups-browsed` conta...2024

🕵️Threat Intelligence

10
Securelist
Exploits and vulnerabilities in Q3 20242024-12-06
Securelist
Analyzing the vulnerability landscape in Q3 20242024-12-06
Wiz
Crying Out Cloud - October 2024 Newsletter | Wiz2024-10-01
Wiz
OpenPrinting CUPS Vulnerabilities: Analysis of related CVEs | Wiz Blog2024-09-29
Wiz
OpenPrinting CUPS Vulnerabilities: Analysis of related CVEs | Wiz Blog2024-09-29